CVE-2025-12453

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.  The vulnerability could lead to Reflected XSS attack of cross-site scripting in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X, from 25.1.0 through 25.1.X, from 25.2.0 through 25.2.X, from 25.3.0 through 25.3.X.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*

History

17 Apr 2026, 15:25

Type Values Removed Values Added
CPE cpe:2.3:a:opentext:vertica:*:*:*:*:*:*:*:*
Summary
  • (es) Neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') vulnerabilidad en OpenText™ Vertica permite XSS Reflejado. La vulnerabilidad podría conducir a un ataque de XSS Reflejado de cross-site scripting en la aplicación de consola de gestión de Vertica. Este problema afecta a Vertica: desde 10.0 hasta 10.X, desde 11.0 hasta 11.X, desde 12.0 hasta 12.X, desde 23.0 hasta 23.X, desde 24.0 hasta 24.X, desde 25.1.0 hasta 25.1.X, desde 25.2.0 hasta 25.2.X, desde 25.3.0 hasta 25.3.X.
References () https://portal.microfocus.com/s/article/KM000045852?language=en_US - () https://portal.microfocus.com/s/article/KM000045852?language=en_US - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Opentext
Opentext vertica

13 Mar 2026, 19:53

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:53

Updated : 2026-04-17 15:25


NVD link : CVE-2025-12453

Mitre link : CVE-2025-12453

CVE.ORG link : CVE-2025-12453


JSON object : View

Products Affected

opentext

  • vertica
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')